CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 43

As cited

Copy frozen at (site build).

threat intel

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Unknown threat actors are distributing malicious installer archives through spoofed websites that mimic legitimate software tools. The campaign uses ScreenConnect remote access software to deploy AsyncRAT malware across multiple domains and languages. Kaspersky identified this as a large-scale operation targeting users seeking common applications like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.

Why it matters: AsyncRAT provides attackers with remote code execution capabilities; users should verify software authenticity through official vendor sites and avoid downloads from search results.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Unknown threat actors are distributing malicious installer archives through spoofed websites that mimic legitimate software tools. The campaign uses ScreenConnect remote access software to deploy AsyncRAT malware across multiple domains and languages. Kaspersky identified this as a large-scale operation targeting users seeking common applications like OBS Studio, DNS Jumper, DS4Windows, and Bandicam.

Why it matters: AsyncRAT provides attackers with remote code execution capabilities; users should verify software authenticity through official vendor sites and avoid downloads from search results.

VendorsConnectWise
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary